S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 6, 2026

CVE-2018-6961 Scanner

CVE-2018-6961 Scanner - Command Injection vulnerability in VMware NSX SD-WAN Edge

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-6961
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
NSX SD-WAN by VeloCloudby VMware
prior to version 3.1.0
Updated Aug 21, 2026View on NVD →
Detail

VMware NSX SD-WAN Edge is a platform used by enterprises and service providers to deliver wide area network (WAN) connectivity as a service. It allows for improved performance and management of network resources. Organizations use this platform to ensure reliable and scalable network operations. Deployments can involve numerous branches and serve thousands of users, optimizing network traffic. NSX SD-WAN Edge enables seamless integration with cloud and on-premises services. It is designed to enhance network security and performance further.

The Command Injection vulnerability allows attackers to execute arbitrary commands on a vulnerable system. This is particularly dangerous because it can lead to unauthorized access and control of the affected device. It is often exploited by injecting harmful commands into web application interfaces. Unauthenticated attackers can manipulate application inputs to execute these commands. This results in unauthorized operations being performed on the host system. It is a critical vulnerability that organizations must address promptly to safeguard their infrastructures.

The vulnerability has been identified in the local web UI diagnostic tools (Ping/Traceroute) of VMware NSX SD-WAN Edge. By manipulating the 'destination' parameter, attackers can inject system commands. Specifically, using backticks or shell syntax allows command execution. The POST request to '/scripts/ajaxPortal.lua' endpoint is susceptible. If not properly sanitized, the parameter allows arbitrary command execution. Therefore, the integrity of network operations may be jeopardized.

Exploitation of this Command Injection vulnerability can have severe consequences, including unauthorized control over the system. Malicious users could execute arbitrary code with elevated privileges, potentially compromising sensitive data. The integrity and availability of network services may be affected. Unauthorized access to critical network resources can lead to further exploitation. Consequently, the overall security of the network infrastructure can be severely undermined. Organizations should address this risk by applying security patches and enhancing input validation mechanisms.

REFERENCES

Solution Advice
  • Upgrade to VMware SD-WAN Edge version 3.1.2 or later.
  • Remove or disable the diagnostic web UI component if not needed.
  • Implement proper input validation on user-supplied data to prevent command injection.
  • Regularly audit and monitor logs for any suspicious activities.
  • Apply security patches at the earliest opportunity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-6961 Scanner - Command Injection vulnerability in VMware NSX SD-WAN Edge | S4E